How does GDPR apply to referral programs?
The central issue is that a referral collects personal data about someone who has no relationship with you — the referred friend. Asking advocates to submit friends' email addresses creates a lawful-basis problem. Share-link designs, where the friend chooses to click, largely avoid it.
- The core risk is processing data about a referred person who has no relationship with you.
- Collecting friends' email addresses from advocates creates a lawful-basis problem under GDPR.
- Share-link designs largely avoid it, because the referred person initiates contact themselves.
- Document retention, attribution storage and deletion handling for pending referrals.
- This is general information, not legal advice.
Why is collecting a friend's email a problem?
Because you are processing personal data about someone who has not given consent and has no relationship with you, obtained from a third party. Under GDPR you would need a lawful basis and, generally, to inform that person — which is difficult when they never contacted you.
This is why the 'enter your friend's email and we will message them' pattern has largely disappeared from European programs.
A share-link design inverts it: the advocate shares a link through their own channel, and the friend initiates contact by clicking. You process their data only once they engage directly with you.
What is the safer program design?
Give the advocate a link or code they share themselves, through their own email, message or social channel. You never receive the friend's details until that person voluntarily arrives on your site, at which point normal signup consent applies.
What else should the program document?
Retention periods for referral records, how attribution data is stored, what happens to a pending referral if either party requests deletion, and whether reward data is shared with a payout provider. These are ordinary obligations that referral programs frequently overlook.
What happens to a referral if someone requests deletion?
Decide in advance. If the referred person exercises erasure while a reward is pending, you need a documented position on whether the referral still qualifies — and you generally cannot retain their personal data purely to justify paying someone else.
Do referral cookies need consent?
Under EU rules, non-essential cookies require consent, and attribution cookies are typically not classed as strictly necessary. That means a referral click may not be trackable at all if the visitor declines — which should shape how you measure rather than being discovered later.
How long should referral data be kept?
Only as long as it serves a stated purpose. A reasonable position is to keep attribution records while a reward could still be claimed or disputed, then delete or aggregate. Indefinite retention of referral graphs is difficult to justify against data-minimisation obligations.
Does sharing a referral link count as processing?
Not on your side, which is precisely the advantage of the design. When an advocate shares a link through their own email or messaging app, that sharing happens outside your systems — you process nothing about the recipient until they choose to visit you.
- Share-link design — the referred person initiates contact themselves
- Friend-email collection — you process a third party's data without their consent
- Contact-list upload — the highest risk pattern; largely abandoned in Europe
- Social share — the platform handles delivery, not you
Can you collect a friend's email address for a referral under GDPR?
It is difficult to do lawfully. You would be processing personal data about someone with no relationship to you, obtained from a third party, which requires a lawful basis and generally an obligation to inform them. Share-link designs avoid the problem.
What is the GDPR-safe way to run a referral program?
Give the advocate a link or code to share through their own channels. You only process the referred person's data once they voluntarily arrive on your site, where normal signup consent applies.
- EUR-Lex (Regulation (EU) 2016/679, Article 6) — Lawfulness of processing under the GDPR
Last reviewed 4 August 2026.
Put this into practice
ReferralFlo handles the tracking, reward rules and fraud screening these pages describe — without engineering time.
